Removing hacked data: what is possible
Can hacked personal data be deleted? What you can have removed (original site, Google, directories) and what is out of reach.
Let us be clear from the start: copies already in hackers' hands cannot be deleted. Nobody, neither a paid service nor an authority, can get them back. You can, however, greatly reduce the information available about you and make leaked data useless.
What you can have removed
Data held by the hacked site
The GDPR (Article 17) lets you require an organisation to erase the data it keeps about you, especially if you no longer use its service. It has one month to reply. The less it keeps, the less a future breach can affect you. Template and deadlines in GDPR erasure request.
Your unused accounts
Every forgotten old account is a potential breach. Close the ones you no longer need, asking for the data to be deleted, not just the account deactivated.
Search results
If your address, phone number or other contact details appear in Google results, you can ask for their removal with Google's "Results about you" tool. Delisting removes the link from results, not the page itself.
Directories and sites republishing your information
Send them an erasure or objection request, as with any organisation. Without a reply within a month, you can complain to your data protection authority.
What is out of reach
- Databases already copied, resold or published on forums and the dark web;
- data that scammers have already reused.
Be wary of any offer promising to "remove your data from the dark web": it is impossible.
Making stolen data useless
- Password: change it everywhere it was used.
- Bank card: block it and request a new one.
- Email: turn on two-factor authentication and stay extra alert to phishing.
We can do it for you
After checking your address, SimplComIA can send erasure requests to the sites concerned on your behalf, with automatic reminders, or give you letters ready to send.